Jonkman Microblog
  • Login
Show Navigation
  • Public

    • Public
    • Network
    • Groups
    • Popular
    • People

Conversation

Notices

  1. GeniusMusing (geniusmusing@nu.federati.net)'s status on Friday, 22-Oct-2021 22:34:24 EDT GeniusMusing GeniusMusing
    Embedded malware in ua-parser-js · GHSA-pjwm-rvh2-c87w · GitHub Advisory Database · GitHub
    https://github.com/advisories/GHSA-pjwm-rvh2-c87w

    >The npm package ua-parser-js had three versions published with malicious code. Users of affected versions (0.7.29, 0.8.0, 1.0.0) should upgrade as soon as possible and check their systems for suspicious activity. See this issue for details as they unfold.
    >
    >Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.
    In conversation Friday, 22-Oct-2021 22:34:24 EDT from nu.federati.net permalink

    Attachments

    1. Invalid filename.
      GHSA-pjwm-rvh2-c87w - GitHub Advisory Database
      from GitHub
      Embedded malware in ua-parser-js
    1. lnxw48a1 (lnxw48a1@nu.federati.net)'s status on Friday, 22-Oct-2021 22:47:20 EDT lnxw48a1 lnxw48a1
      in reply to
      @geniusmusing Given the large number of programs that use #Node.js under the hood, one may not know that anything is being pulled in from #npm. Huge potential for system compromise.
      In conversation Friday, 22-Oct-2021 22:47:20 EDT from nu.federati.net permalink
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

Jonkman Microblog is a social network, courtesy of SOBAC Microcomputer Services. It runs on GNU social, version 1.2.0-beta5, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All Jonkman Microblog content and data are available under the Creative Commons Attribution 3.0 license.

Switch to desktop site layout.